Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

FTP Passive problem

Hello, I am having a problem where I cannot FTP in passive mode using an external IP to my FTP server behind the Fortigate 60B. When I FTP using the internal IP address the FTP works fine to the FTP server. The first item I noticed is when I use a FTP client the passive port range is not being used. I have used several different FTP clients such as WSFTP and Filezilla. If I eliminate the Fortigate the FTP works fine. The following is an example of the FTP external IP failure: PASV 227 Entering Passive Mode (208,xx,xx,66,132,187) connecting to 208.xx.xx.66:33979 - - connecting to 208.xx.xx.66:33979 ! Connection failed 208.xx.xx.66 - connection timed out ! connect: error 0 When it times out the FTP shifts into regular FTP and works fine. The fact that the login works and I get this far tells me the the FTP port is open. This following is an example when the FTP works using the internal IP address. PASV 227 Entering Passive Mode (208,xx,xx,66,92,28) connecting to 208.xx.xx.66:23580 - - connecting to 208.xx.xx.66:23580 Connected to 208.xx.xx.66 port 23580 This FTP works fine and it is using the FTP passive port range (23580-23590) that I assigned to the serv-u FTP server. My experineces with other routers is I have to open ports with port forwarding. I am not sure if this is the case with the Fortigate. Any guidence would be most welcome. Thank You, Joe
14 REPLIES 14
Not applicable

Hey Joe, On the initial connection are you using a custom port? I had this issue where passive could open the initial control connection but couldn' t open the data connection. You can solve this issue by adding a session-helper for the custom port. This way the Fortigate knows to treat traffic on the initial custom port as FTP and will allow temporary conduits to be opened on the passive range for the data channel. config sys session-helper edit 0 set name ftp set port 2121 (port that FTP is listening on for control goes here) set protocol 6 next end hope that helps.
Not applicable

Thank You for your response. But, I still have the same problem. Once again Thanks, Joe
Not applicable

What does your VIP configuration look like for this IP? Firewall->Virtual IP
Not applicable

Hello, Here is the VIP Name: VIP-MXWFTP External Interface: WAN1 Type: Static NAT External IP: 208.XX.XX.66 Mapped IP: 192.168.210.66 Port Fowarding: Unchecked Joe
rwpatterson
Valued Contributor III

See the end of this post...

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

loop rwpatterson: that thread links back to my post above in this thread . . . nice!
rwpatterson
Valued Contributor III

Ooooops...LOL

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

Thank you for looking in to it. I agree with you either the FTP program is passing the wrong PASV port back or the Fortigate is not translating the port correctly. Just for grins I change the passive ports to what Fortigate thinks it should be (in my case port 37988) and it also fails. I also find it interesting that it falls back into regular FTP and works. Joe
UkWizard
New Contributor

A very obvious question, but someone has to ask it. You do have NAT unchecked on the inbound policy, dont you?
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors